MEDIUM🇵🇱 Wersja polska

CVE-2025-46775

CVSS 5.5v3.1pub. 2025-11-18upd. 2025-11-20

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated user to obtain administrator credentials via debug log commands.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
  • Fortinet Fortiextender

    HW
    Fortinet
    all versions
  • Fortinet Fortiextender Firmware

    OS
    Fortinet
    7.0.0 – 7.4.8 (excl.)7.6.0 – 7.6.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-64153HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2024-23663HIGH8.8same product

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0...

CVE-2022-23447HIGH7.5same product

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fo...

CVE-2022-27489HIGH7.2same product

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet Forti...

CVE-2021-41016HIGH7.8same product

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtende...